BigBear Phishing Bypasses Microsoft 365 MFA at 258 Organizations
CloudSEK found BigBear 2.0 stealing Microsoft 365 session cookies after MFA. Revoke sessions, rotate credentials and require phishing-resistant sign-in.
Read article →Reader view
Choose the default article length.
Authentication, access, credentials, and identity systems.
CloudSEK found BigBear 2.0 stealing Microsoft 365 session cookies after MFA. Revoke sessions, rotate credentials and require phishing-resistant sign-in.
Read article →Customer-managed VPN and AAA appliances need branch-specific fixed builds; configuration determines exposure on later NetScaler releases.
Read article →A recovered Sliver kit shows how one operator scripted Domain Admin access, disabled defenses, stole credentials, and hid rotating command servers behind Ethereum.
Read article →Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Read article →Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Read article →A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Read article →Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
Read article →Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →